2GD Solutions Limited ("The GD Studio") respects your right to privacy. This privacy notice
("Privacy Notice") explains who we are, how we collect, share and use personal information
about you, and how you can exercise your privacy rights. This Privacy Notice covers your access, use and
engagement with us in relation to our game, Diabotical. Specifically, this Privacy Notice covers personal
information we obtain in relation to your use of our website at https://www.diabotical.com/ ("Website") and information we collect
when you use our online game, Diabotical, made available at https://www.epicgames.com/store/en-US/product/diabotical/home ("Diabotical").
If you have any questions or concerns about our use of your personal information, then please contact us using
the contact details provided at the bottom of this Privacy Notice.
What does The GD Studio do?
The GD Studio is an online game developer offering our game, Diabotical, to users through the Epic Games Online
Store (available at: https://www.epicgames.com/store/en-US/). More information
about Diabotical can be found at: https://www.diabotical.com/faq.
What personal
information does The GD Studio collect and why?
The personal information that we may collect about you broadly falls into the following categories:
1. Information we collect via our
Website
1.1 Information that you provide to us directly:
Certain parts of our Website may ask you to provide personal information voluntarily: for
example, we may ask you to provide your contact details in order to subscribe to our newsletter and/or to
respond to any enquiries.
We will also collect personal information from you where you choose to enter one of our competitions or
tournaments. Generally, this will include your full name, email address, home city and date of
birth. This is to ensure competition entries comply with the relevant competition terms (such as any age
restrictions or to confirm single entry) and to identify and contact you, should you win.
If you are entering on behalf of a team, you may also provide us with this information about each of your
teammates. By providing us with this information, you confirm that: (i) you have made your teammates aware of
this Privacy Notice; and (ii) your teammates understand that we will receive and use their information in
accordance with this Privacy Notice.
In the event you (or your team) are the winner of any of our competitions or tournaments, we will also require
further information in order to award you your prize. For example, we may require you to present personal
identification documents to prove your age and identity. If the prize is a monetary award, we may need to
collect your PayPal account details (so we can transfer the prize to you); or, if the prize is goods, we will
need your delivery address (so we can deliver your prize to you).
For one month after the end of the entry period, upon request, we will inform any entrant(s) who has not won our
competition or tournament of the name and home city of the winner. We may then use your name and home city for
further publication purposes on our Website or other social media channels in order to announce you as the
competition winner, if you have agreed that you are happy for us to do so.
1.2 Information that we collect automatically:
When you visit our Website, we may collect certain information automatically from your device. In some countries,
including the UK and the European Economic Area, this information may be considered personal information under
applicable data protection laws.
Specifically, the information we collect automatically may include information like your IP address, device type,
unique device identification numbers, browser-type, broad geographic location (e.g., country or city-level
location) and other technical information. We may also collect information about how your device has interacted
with our Website, including the pages accessed and links clicked.
Collecting this information enables us to better understand the visitors who come to our Website, where they come
from, and what content on our Website is of interest to them. We use this information for our internal analytics
purposes and to improve the quality and relevance of our Website to our visitors.
1.3 Information that we obtain from third party sources
You can access our pages on third party social media sites through our Website, such as Trello,
Reddit, Discord,
Twitter and Youtube.
These websites are hosted and operated by separate
third parties and may enable user-generated content features. Please be aware that The GD Studio does not
control these websites and is not responsible for the manner in which they operate. However, we may receive
aggregated engagement information from them in relation to your activity on our page(s), such as page views,
likes, dislikes, tweets, retweets, replies, follows, favourites, links, mentions, hashtags, or subscriptions to
our channels. Please review the privacy notices provided by the operators of each of these websites if you would
like further information about how these third parties collect, use and share your data, your privacy rights and
how to change your privacy settings.
2. Information we collect via
Diabotical
2.1 Information we obtain from Epic Games:
Purchasing/Downloading Diabotical
When you purchase or download Diabotical through the Epic Games Online Store, you have the opportunity to do this
using your Epic Game login credentials. If you choose this option, please be aware that this is information that
has been previously collected by (and is processed by) Epic Games in accordance with their own privacy notice
and terms (available: https://www.epicgames.com/site/en-US/privacypolicy).
When you play Diabotical, Epic Games will share certain information associated with your account with us, in
order for us to support your gameplay and to allow us to contact you, where permitted by law. This information
will include your Epic account ID, your entitlement to the game and contact details provided as part of your
Epic Games account.
Enabling in-game features
In order to enable certain features within Diabotical (such as match-making and use of the "Friends List"), Epic
will share with us your Epic display name, your unique account identifier and other basic profile information
(such as your country, language preferences and Epic friends list). We may also receive information about your
online presence, for example: whether you are online or offline; what game you are playing; and a transaction ID
if you have made an in-game purchase.
If we choose to leave the Epic Games platform, Epic will also transfer to us any information that is necessary
for us to support your continued gameplay on our new platform, so you can continue playing. If we choose to
change platforms, we will let you know in advance.
Analytics and Analysis
When you play Diabotical, Epic Games may run analytics and analysis across your interaction with Diabotical and
other games you play through the Epic Games platform. This information is obtained by Epic Games and will be
processed by them in accordance with their own privacy notice and terms. Epic Games may share this information with us in
order for us to understand how players interact with Diabotical and other games on the Epic Games platform; and
so, we can better improve Diabotical for players.
2.2 Information we obtain directly from you or your device
Playing our Game
When you play Diabotical, we may obtain further information from you directly. For example, we may collect:
• Player information from you, such as your status within a game, your score and ranking as well as any
friends you may connect with through Diabotical.
• Online identifiers such as your in-game alias, IP address, identifiers that we assign to your account, or
information about your hardware or operating system based on your identifiers.
• Technical information about the device you use to play Diabotical (for example, information about its type,
model, manufacturer, operating system, language, display, processor or memory).
• Your general location (for example, country, state or city) inferred from your IP address.
• Information about your use of Diabotical (for example, information about your progress in our game).
• Crash logs or other information related to bugs, errors or other issues with Diabotical.
• Inferences that we make based on your activity in Diabotical.
• Where you use in-game social features such as messaging / live audio, (for example, if you send chat
messages in Diabotical) your messages will be sent to the message recipient through our systems. However, we
do not store written messages; and we encrypt and hash any audio communications that we retain (i.e. so we
cannot access the underlying audio content once it has been sent). We only use these hashed files for the
purposes of verifying user claims concerning the use of offensive language or other breaches of our Terms of
Service (https://www.diabotical.com/terms), as further
described in our Terms of Service.
• If you choose to submit maps to us through the in-game map editor, we may collect your chosen nick-name to
list you as map author.
• Any other information you choose to submit to us through Diabotical or otherwise.
• Any other information, with your consent.
We do not expect or intend to collect or otherwise process any special categories of data relating to you. This
includes your genetic, biometric or health information, information revealing racial or ethnic origin, sex life
or sexual orientation, political opinions, religious or philosophical beliefs or trade union membership, or
information about your criminal offences or convictions. Please do not provide this sort of information to use
or use Diabotical to make it available to others.
2.3 Information that we obtain from third party sources (other than Epic Games)
From time to time, we may receive personal information about you from third party sources (including social media
and gaming console companies, where you have an account), but only where we have checked that these third
parties either have your consent or are otherwise legally permitted or required to disclose your personal
information to us.
Where you have chosen to play Diabotical via a third-party account, the types of information we collect from such
third parties may include details of your profile on the relevant third-party platform (such as your name,
avatar, email, country and friends lists). We use this information for the purposes described in this Privacy
Notice.
2.4 How we use the information we collect in relation to Diabotical
We typically use the information we receive about you in relation to Diabotical:
• To enable you to play Diabotical.
• To provide you with the correct version of Diabotical (for example, selecting an appropriate language
version for you).
• where available, to enable you to communicate with other users in Diabotical (for example, by enabling
in-game chat or similar features).
• To send you service-related communications (for example, technical notices, security alerts and
administrative messages).
• To operate and maintain Diabotical (for example, by making sure Diabotical is secure and functions as
intended).
• To troubleshoot or debug any bugs, errors or other issues.
• To measure and analyse the use of Diabotical or data we collect through Diabotical (for example, to discover
trends or other insights).
• To improve Diabotical or develop new services.
• To conduct surveys or other research to learn more about our users.
• To create aggregated and anonymised data that does not identify you, so we can use this freely.
• To personalise your gameplay in Diabotical based on your activity.
• To provide you with offers and rewards in Diabotical based on your activity.
• Where available, to enable your gameplay across multiple devices.
• Where available, to provide social features (e.g. match-making, leader boards) or other events in
Diabotical.
• To respond to support requests or otherwise manage our relationship with you.
• To ensure Diabotical is a safe and fair environment for all users by moderating and monitoring the use of
Diabotical (including any messages sent through Diabotical), either automatically or manually.
• To ensure that our Terms of Service (https://www.diabotical.com/terms) are complied with.
• Where permitted by law, to send you communications about Diabotical and other offers, rewards or news that
we think you may be interested in.
• To detect, investigate or prevent fraud or fraudulent behaviour.
• Where permitted or required for our legal or compliance obligations.
• For any other purposes, where we have your consent.
Who does The GD
Studio share my personal information with?
We may disclose your personal information to the following categories of recipients:
• to our group companies, third party services providers and partners who provide data
processing services to us (for example, to support the delivery of, provide functionality on, or help to
enhance the security of our Website or Diabotical), or who otherwise process personal information for
purposes that are described in this Privacy Notice or notified to you when we collect your personal
information.
• to any competent law enforcement body, regulatory, government agency, court or other third party
where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to
exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any
other person;
• to an actual or potential buyer (and its agents and advisers) in connection with any actual
or proposed purchase, merger or acquisition of any part of our business, provided that we inform the buyer
it must use your personal information only for the purposes disclosed in this Privacy Notice;
• to any other person with your consent to the disclosure.
Legal basis for processing personal information (EEA and UK individuals only)
If you are a player from the European Economic Area or the UK (or you visit our website from the EEA or the UK),
our legal basis for collecting and using the personal information described above will depend on the personal
information concerned and the specific context in which we collect it.
1. Our Website
When you visit our website, we will normally collect personal information from you only (i)
where we need the personal information to perform a contract with you (e.g. if we need this information to
provide you with a service you have requested); (ii) where the processing is in our legitimate interests and are
not overridden by your rights (e.g. where we are carrying out analytics on our website usage; or responding to a
query that you have sent to us), or (iii) where we have your consent to do so (e.g. where you have signed up to
our mailing list).
When you enter one of our competitions or tournaments, we will normally collect personal
information from you (i) where we need the personal information to perform a contract with you (e.g. where you
have submitted an entry to the competition, to run the competition; or where we need to provide you with your
prize); (ii) where we are under a legal obligation to collect this information from you (e.g. to verify your age
prior to competition entry); or (iii) where we have your consent to do so (e.g. where you are announced as a
winner and we wish to publish your details).
Where we need your information for the purposes of fulfilling our contract with you in relation to a competition,
or because of our legal obligations in relation to the same, you will not be allowed to enter the competition
(or win a prize) if you do not provide us with this information.
2. Diabotical
When you play Diabotical, we collect personal information from you only (i) where we need the personal
information to perform a contract with you (i.e., to give you access to Diabotical and let you play the game);
(ii) where the processing is in our legitimate interests and not overridden by your rights (i.e., to carry out
in-game analysis and analytics to improve Diabotical or develop new games), or (iii) where we have your consent
to do so. In some cases, we may also have a legal obligation to collect personal information from you (i.e. to
verify your age in order to play the game) or may otherwise need the personal information to protect your vital
interests or those of another person.
If we ask you to provide personal information to comply with a legal requirement or to perform a contract with
you, we will make this clear at the relevant time and advise you whether the provision of your personal
information is mandatory or not (as well as of the possible consequences if you do not provide your personal
information).
If you have questions about or need further information concerning the legal basis on which we collect and use
your personal information, please contact us using the contact details provided under the “How to contact us”
heading below [link].
Cookies and similar tracking
technology
We only use cookies and similar tracking technology (collectively, “Cookies”) where they are
strictly necessary to make our Website or Diabotical work. Without these Cookies, we would not be able to
provide you with our Website or Diabotical or keep them secure. You may still be able to disable these by
changing your browser settings, but this may affect how the Website or Diabotical functions.
How does The GD
Studio keep my personal information secure?
We use appropriate technical and organisational measures to protect the personal information that we collect and
process about you. The measures we use are designed to provide a level of security appropriate to the risk of
processing your personal information. Specific measures we use include – e.g., encrypting your personal
information in transit and at rest.
International data transfers
Your personal information may be transferred to, and processed in, countries other than the country in which you
are resident. These countries may have data protection laws that are different to the laws of your country.
Specifically, our servers are located worldwide; and our group companies, partners and third-party service
providers operate around the world. This means that when we collect your personal information, we may process it
in any of these countries.
However, we have taken appropriate safeguards to require that your personal information will remain protected in
accordance with this Privacy Notice.
Data retention
We only retain information where we have an ongoing legitimate business need to do so (for example, to provide
you with a service you have requested or to comply with applicable legal, tax or accounting requirements).
When we have no ongoing legitimate business need to process your personal information, we will either delete or
anonymise it or, if this is not possible (for example, because your personal information has been stored in
backup archives), then we will securely store your personal information and isolate it from any further
processing until deletion is possible.
Automated decision-making
In some instances, our use of your personal information may result in automated decisions being taken that impact
your ability to use Diabotical.
Automated decisions mean that a decision concerning you is made automatically on the basis of a computer
determination (using software algorithms), without our human review. For example, we use an automated anti-cheat
system, to automatically flag if certain activities suggest that you are cheating or using Diabotical in breach
of our Terms of Service. If we conclude that you have been cheating, or breaching our Terms of Service, we may
restrict you from playing Diabotical in the future.
When we make an automated decision about you, you have the right to contest the decision, to express your point
of view, and to require a human review of the decision. You can exercise this right by contact us using the
contact details provided under the “How to contact us” heading below.
Your data protection rights
You have the following data protection rights:
• If you wish to access, correct, update or request deletion of your personal information,
you can do so at any time by contacting us using the contact details provided under the “How to contact us”
heading below.
• In addition, you can object to processing of your personal information, ask us to
restrict processing of your personal information or request portability of
your personal information. Again, you can exercise these rights by contacting us using the contact details
provided under the “How to contact us” heading below.
• You have the right to opt-out of marketing communications we send you at any time. You can
exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you.
To opt-out of other forms of marketing (such as postal marketing or telemarketing), then please contact us
using the contact details provided under the “How to contact us” heading below.
• Similarly, if we have collected and process your personal information with your consent, then you can
withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness
of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal
information conducted in reliance on lawful processing grounds other than consent.
• You have the right to complain to a data protection authority about our collection and use
of your personal information. For more information, please contact your local data protection authority.
Updates to this Privacy Notice
We may update this Privacy Notice from time to time in response to changing legal, technical or business
developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent
with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes
if and where this is required by applicable data protection laws.
You can see when this Privacy Notice was last updated by checking the “last updated” date displayed at the top of
this Privacy Notice.
How to contact us
If you have any questions or concerns about our use of your personal information, please contact us using the
following details: privacy@thegdstudio.com
The data controller of your personal information is 2GD Solutions Limited.